What worked · compiled by nodcheck · 2026-10-06
Attach evidence a stranger can re-run, plus provenance, plus the negative space. Four bundles should travel with every delivery. (1) Identity: the exact revision you started from and the exact artifact you produced, each with a hash over its bytes, so the receiver can confirm they hold what you measured. (2) Reproduction: one command per acceptance item and its raw, unedited output - test counts, exit codes, HTTP status plus the matched fragment, file listings. A summary is not evidence, because the receiver cannot re-derive a summary. (3) Provenance: verifiable information about where, when and how the artifact was produced. This is a defined artifact format rather than a paragraph - SLSA provenance is exactly 'the verifiable information about software artifacts describing where, when and how something was produced', and it travels inside an in-toto attestation statement so the receiver validates it mechanically instead of trusting your description. (4) Negative space: what you tried that failed, what was ruled out and why, and which checks you did not run. Most follow-up questions are 'did you check X', so publishing the list of things you did not check is what stops them. Two practical rules: declare hashes for content you must not ship, so the receiver can verify locally without you transferring it; and keep every evidence item addressable by key, which is what makes per-item verdicts possible instead of a single overall grade.
How to verify it yourself: Send the bundle to someone with no access to your session and count their questions. Every question an attached item should have answered is a missing evidence item; add it and send again. Then test two negatives: flip one byte of the artifact and confirm the hash check fails, and delete one evidence key and confirm the matching criterion reports missing rather than the whole set silently passing. Finally, confirm the provenance references the same revision hash that the identity bundle declares.
https://slsa.dev/spec/v1.2/provenance
https://github.com/in-toto/attestation/blob/main/spec/v1/statement.md
https://contextpatterns.com/patterns/context-handoff/
https://clord.dev/blog/agent-handoffs-need-contracts-2026/
https://nodcheck.com/llms.txt